antique keys hanging on hook on wooden wall

Privacy Policy

Effective date: June 3, 2021 - Previous Update: November 7, 2020

This privacy policy sets out how this website (hereafter "Fiddleheads") uses and protects any information that you give us while using this website (hereafter “Service”).

Fiddleheads is committed to ensuring that your privacy is protected. When we ask you to provide information by which you can be identified when using our Service, you can be assured that it will only be used in accordance with this privacy statement.

[You may also be interested in reading about our Site Security]


Information Collection And Use

We collect several different types of information for various purposes to provide and improve our Service to you. Types of data collected include:

  1. Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information (hereafter “Data”) that can be used to con or identify you, ship your purchases and provide our Service. Personally identifiable information may include, but is not limited to:

  • First and Last name
  • Email Address and Phone Number
  • Mailing & Billing Address
  • Cookies and Usage Data
  • Voluntary demographic information such as preferences, interests, musical experience or that which is relevant to customer surveys and/or offers
  1. Usage Data

We may also collect information how our Service is accessed and used ("Usage Data"). Usage Data may include information such as diagnostic data, your computer's Internet Protocol (IP) address, browser type and version, unique device identifiers, the pages of our Service you visit, and the time, date and duration of your visit.

  1. Tracking & Cookies Data

Cookies are files with small amount of data which may include an anonymous unique identifier. We use cookies and similar tracking technologies to track the activity on our Service and hold certain information relating to details such as session details, your preferences and security.

Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and only to analyze and improve our Service. Click here for the types of cookies Google uses.

From Google (Full Google Data Policies, Click Here)

You can use Ads Settings to manage the Google ads you see and opt out of Ads Personalization. Even if you opt out of Ads Personalization, you may still see ads based on factors such as your general location derived from your IP address, your browser type, and your search terms.

You can also manage many companies’ cookies used for online advertising via the consumer choice tools created under self-regulation programs in many countries, such as the US-based choices page or the EU-based Your Online Choices.

Finally, you can manage cookies in your web browser.

You can configure your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. You can learn more about Google Analytics Cookie Usage on Websites and the associated cookies (which we may or may not collect) here.

Watch this video by Google to better understand cookies.


The table below lists some cookies Fiddleheads may or may not collect and what information they store:

Cookie Name

Cookie Description


Stores randomly generated key used to prevent forged requests.


Your session ID on the server.


Allows guests to view and edit their orders.


A link to information about your cart and viewing history, if you have asked for this.


The store view or language you have selected.


Indicates whether a customer allowed to use cookies.

mage-cache-timeout · section-data-ids · private_content_version · x-magento-vary · mage-cache-storage · mage-cache-sessid · mage-cache-storage-section-invalidation

Facilitates caching of content on the browser to make pages load faster.

mage-translation-file-version · mage-translation-storage

Facilitates translation of content to other languages.

Used to distinguish users (2 years), 
Used to distinguish users (24 hours)
Used to persist session state (2 years)
Contains campaign related info (90 days)

._gat Used to throttle request rate (1 minute). If Google Analytics is deployed via Google Tag Manager, this cookie will be named _dc_gtm_<property- id>
Contains campaign related information for the user (90 days). Google Ads website conversion tags will read this cookie unless you opt-out.

ga.js - cookie usage

The ga.js JavaScript library uses first-party cookies to:

- Determine which domain to measure
- Distinguish unique users
- Throttle the request rate
- Remember the number and time of previous visits
- Remember traffic source information
- Determine the start and end of a session
- Remember the value of visitor-level custom variables

Contains a token that can be used to retrieve a Client ID from AMP Client ID service (30 seconds to 1 year). Other possible values indicate opt-out, inflight request or an error retrieving a Client ID from AMP Client ID service.


Use of Data

Fiddleheads uses the collected data for various purposes:

  • To provide and maintain the Service and usage of the Service
  • To notify you about changes to our Service
  • To provide customer care and support and allow you the choice to participate in interactive features of our Service
  • To provide analysis or valuable information so that we can improve the Service
  • To detect, prevent and address technical issues

Transfer Of Data

Your Data, may be transferred to and maintained on computers located outside your state/province, country or other governmental jurisdiction where data protection laws may differ than those of your jurisdiction.

If you are located outside Canada and choose to provide information to Fiddleheads, please note we transfer the data, including Your Data, to Canada and process it here. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Fiddleheads will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Data will take place to an organization or a country unless there are suitable controls in place including the security of your data and other personal information.

Disclosure Of Data

Legal Requirements

Fiddleheads may disclose your Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of Fiddleheads
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

Security Of Data

The security of your data is important to us, but remember no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Data, we cannot guarantee its absolute security.

[You may also be interested in reading about our Site Security]

Service Providers & Outside Links

We may employ third party companies and individuals to facilitate our Service ("Service Providers"), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing use of our Service. These third parties have access to your Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.


We use Google Analytics and other Google services and may use third-partyService Providers such as Statcounter and AWStats to monitor and analyze the use of our Service who maintain their own Privacy Policies.

  • Visitors can opt-out of the Google Analytics Advertising Features we use, including through Ads Settings, Ad Settings for mobile apps, or any other available means (for example, the NAI's consumer opt-out).
  • You may wish to download Google Analytics' currently available opt-outs browser add-on for the web.
  • For your convenience, you can see Google's contracts and policies about "Personally Identifiable Information" (PII) here.

Links To Other Sites

Our Service may contain links to other sites that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services and strongly advise anyone with questions of concerns to review the Privacy Policy of every site you visit.

Children's Privacy

Our Service does not directly deal with anyone under the age of 18 ("Children") and we do not knowingly collect personally identifiable information directly from anyone under the age of 18 (“Children”) without permission from their parent or guardian. If we become aware that we have collected Data from Children without verification of parental consent, we take steps to remove that information from our servers. If a parent or guardian becomes aware that their Children provided us with Data and the parent or guardian does not approve, please contact us.

Changes To This Privacy Policy

We may update our Privacy Policy from time to time and will notify you of any changes by posting the new Privacy Policy on this page. We will let you know via a prominent notice on our Service prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. If you have any questions about this Privacy Policy, please contact us.